Privacy Policy
We collect what we need to make the platform work, and nothing else. Plain English on what that means in practice.
Last updated July 2026.
Who this applies to
This policy covers everyone who uses Common Elements (“CE,” “we,” “us”): board members, association staff, management company employees, vendors, attorneys, insurance professionals, and anyone visiting our public pages. Common Elements operates from Florida and serves U.S.-based community associations and the businesses around them.
What we collect
The data we collect falls into three buckets:
- Account information you give us: email address, full name, organization name, role within that organization, and (optionally) phone number, biography, avatar, professional credentials (LCAM, license numbers, attorney bar admission), and contact-visibility preferences.
- Content you create on the platform: forum posts, RFPs, proposals, reviews, direct messages, follow relationships, and any documents you upload.
- Operational data we collect automatically: authentication tokens, session timestamps, IP addresses, browser metadata, error reports, and basic usage events (which pages were visited, which actions were taken). We do not run advertising trackers and do not sell or share this data with ad networks.
Browser extension (Common Elements Insight)
Common Elements Insight is an optional Chrome extension. It surfaces HOA and condo association data on real estate listing pages you visit, and, only after you explicitly opt in, collects a small set of factual details from those listings to improve our association database. It is independent and not affiliated with or endorsed by Zillow, Redfin, Realtor.com, or Trulia.
What the extension collects (only with your consent): factual listing details: property address, ZIP, approximate coordinates, list price, bedrooms/bathrooms, living area, HOA fee and frequency, amenities, property type, the association/community name shown on the page, and the address of the listing page itself. These are read from the page’s own public structured data.
What it never collects: listing photographs, written listing descriptions or agent remarks, your browsing history, the identity of which listings you personally viewed as a profile of you, your keystrokes, or data from any site other than the supported listing pages. The extension runs only on listing pages you open yourself; it does not crawl, pre-fetch, or navigate on its own.
Collection is off by default. Nothing is sent until you grant consent in the extension, and you can turn it off at any time from the extension’s settings, which immediately stops all collection. We use the collected facts solely to build and improve the association database that the platform and extension surface back to users.
Anonymous usage statistics: separately from the listing facts above, the extension records which steps it reaches so we can tell when it breaks. These records say things like “installed”, “panel opened”, “a listing was recognised on Zillow”, “no association matched” and whether an expected field was missing. They are tied to a random identifier created when you install the extension, which is not derived from you, your device, or your Google account, and is destroyed when you remove the extension. They never include addresses, listing content, page URLs, or anything you type. You can turn this off in the extension’s settings.
Our use of information received from the Common Elements Insight extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use the data described above only to provide and improve the association-data features of the extension and platform. We do not sell it, use it for advertising, or transfer it to determine creditworthiness or for lending purposes.
Mobile application
The Common Elements app for iOS and Android collects the same account information and platform content described above. A handful of things are specific to a phone. Every one of them is optional, is requested only when you use the feature that needs it, and the app keeps working if you decline.
- Precise location: used only to geotag a site walkthrough you are recording. It is read while the app is open, never in the background, and the walkthrough saves normally if you decline. We do not build a location history and we do not track your movement between walkthroughs.
- Camera and photo library: used when you attach a photo, set a profile picture, scan a governing document, or ask for AI help drafting an RFP scope. The app opens the camera or the picker only when you tap the control that needs it, and it reads only the images you select.
- Microphone and speech recognition: used to dictate meeting notes and motion text. Transcription runs on your device. If a device cannot do on-device recognition, the app tells you dictation is unavailable there rather than sending your audio to a speech service. The recognized text becomes part of the note you are writing; the audio itself is never uploaded or stored by us.
- Document scanning: text recognition on pages you scan runs on your device using the operating system text recognizer. The recognized text is uploaded when you save the document, the same as text you type in yourself.
- Calendar: write-only. When you choose to sync a meeting, the app adds that event to a Common Elements calendar on your device. It never reads, stores, or transmits the events already on your calendar.
- Push notifications: if you allow them, the device push token is stored alongside your account so we can deliver the notifications you turned on. It is a device identifier, not an advertising identifier.
The mobile app contains no analytics SDK and no crash-reporting SDK. It records no screen views, taps, or usage events, and it carries no advertising, attribution, or data-broker SDK of any kind. It never asks for App Tracking Transparency permission, because there is nothing to track. The app does check our update service for app updates, which is delivery, not measurement.
You can delete your account from inside the app under Settings. That runs the same deletion described under “Your rights” below rather than sending you to the website.
How we use it
We use the data above to operate the platform, authenticate users, route notifications, deliver email, prevent abuse, investigate security incidents, debug errors, and improve the product. Membership status determines what you can see on the platform. That’s enforced at the database level, not by UI hiding.
We do not sell personal information, and we do not share it with advertisers. We use AI only in the limited way described under “AI features” below, and never to train an outside provider’s general models.
AI features
We use AI in a small number of places, and only when you ask for it. In each case the content you submit is sent to our AI provider (Anthropic) through our own servers. Our provider credentials stay on our servers and are never shipped inside the mobile app. There are three of these features:
- Document analyzer: the text of a governing document you upload, read and summarized against the relevant statutes, and used to extract basic facts such as association name, dates, and unit count. Governing documents can contain personal data such as owner names, addresses, and unit identifiers, so we treat this the same as the rest of your content.
- Budget and reserve study import: a budget or reserve study file you choose to import, read so its figures can be turned into a structured draft you review and edit.
- Site photo assist: a photograph you take or pick while drafting an RFP scope, described so the scope can be pre-filled. The app captures these photos with EXIF metadata disabled, so no embedded location or camera detail travels with the image.
Content submitted to these features is processed only to return your result. It is not used to train the provider’s models, and the provider retains it only transiently under our contract. The AI extracts, describes, and summarizes; it does not give legal advice or decide whether anything in your document is enforceable.
Service providers
To run the platform we share specific data with a small set of vetted service providers, each under contract:
- Supabase (PostgreSQL hosting, authentication, file storage). All account and platform content data.
- Vercel (web hosting, edge networking). Request metadata and edge cache.
- Resend (transactional email delivery). Email addresses and message bodies for notifications and platform emails.
- Stripe (billing, when paid plans launch). Customer record and payment metadata; no card numbers ever touch our servers.
- Sentry (error monitoring, web platform only). Stack traces and request metadata for errors. Personally identifying details are scrubbed where feasible. The mobile app has no crash reporter and sends nothing to Sentry.
- Anthropic (AI processing). The text of a document you choose to analyze, the budget or reserve study files you choose to import, and the site photographs you submit for RFP scope assist. Sent only to return your result. Not used to train the provider’s models; retained only transiently under our contract. See “AI features” above.
Cookies and similar technology
We use cookies that are strictly necessary to keep you signed in and to remember your in-product preferences (such as your active organization context and notification preferences). We do not set third-party advertising cookies.
Retention
We keep your account data for as long as your account is active. Forum posts, RFPs, proposals, reviews, and messages persist for the operational lifetime of the platform so that audit trails remain intact for boards and counsel. That’s a fiduciary expectation, not a marketing one. Server logs and error reports are retained for up to 90 days. If you close your account, we retain content you authored in shared contexts (forum posts, RFPs, reviews) but disassociate it from your identifying account information unless we’re legally required to keep it linked.
Your rights
You can request a copy of your personal data, correct inaccuracies, restrict processing, or ask us to delete your account by emailing privacy@commonelements.com. If you’re a California resident, you have additional rights under the California Consumer Privacy Act; if you’re based in the EEA or UK, GDPR rights apply. We respond to verified requests within 30 days.
Security
Account access requires authentication. Database row-level security ensures users only see what their organization membership entitles them to. Production traffic is HTTPS-only with strict transport security; HSTS, frame-busting, and a content security policy are enforced at the application edge. We rotate credentials, scan dependencies for known vulnerabilities, and document our incident response procedure.
No system is impervious. If we discover a security incident that affects your data, we’ll tell you what happened, what we did about it, and what you should do, without spin.
Children
Common Elements is not directed at children under 13 and we do not knowingly collect data from them. If you believe a minor has created an account, contact us and we’ll delete it.
Changes to this policy
We’ll update this page when our practices change. Material changes are announced via in-app notification and email at least 30 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.
Contact
Common Elements
Florida, USA
privacy@commonelements.com